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Top Stories 

• Officials reported May 19 a settlement with the Takata Corporation in which the air bag 
manufacturer agreed to declare 33.8 million of its inflator mechanisms defective, leading to 
the largest recorded U.S. auto recall - NBC News (See item 2 ) 

• Five major banks agreed to plead guilty and pay $6 billion May 20 in a settlement with 
authorities to resolve charges of foreign currency exchange manipulation that had occurred 
until regulators started punishing banks for the misconduct in 2013 - Reuters (See item 3 ) 

• Six train tankers carrying hazardous chemicals derailed in Louisiana, May 19, prompting 
officials to declare a state of emergency and a mandatory evacuation for residents within 
1,000 feet of the area - NBC News (See item 6) 

• Federal authorities and agencies in all 50 States filed a joint lawsuit May 18 against the 
Tennessee -based Cancer Fund of America, its 3 affiliated nonprofits, and the individuals 
who run the charities for allegedly using the $187 million raised for personal use- 
Knoxville News Sentinel (See item 14 ) 
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Energy Sector 

1. May 20, U.S. Environmental Protection Agency - (Indiana; Kentucky; Ohio) U.S. 
settles with Marathon Petroleum Corporation to cut harmful air emissions at 
facilities in Indiana, Kentucky, and Ohio. The U.S. Environmental Protection 
Agency and the U.S. Department of Justice reached a settlement May 19 with 
Marathon Petroleum Corporation resolving a number of alleged Clean Air Act 
violations, including the company’s failure to comply with Federal fuel quality 
emissions standards and recordkeeping, sampling, and testing requirements at 10 
facilities in Indiana, Kentucky, and Ohio. The company will pay a $2.9 million civil 
penalty, spend over $2.8 million on pollution controls, retire 5.5 billion sulfur credits, 
and take steps to reduce harmful air pollution emissions. 

Source: 

http://vosemite.epa.gOv/opa/admpress.nsf/0/07CE680B3FE75B8485257E4A005E1853 
For additional stories, see times 4 and 12 
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Chemical Industry Sector 

See item 6 



[ Return to top ] 

Nuclear Reactors, Materials, and Waste Sector 

Nothing to report 
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Critical Manufacturing Sector 

2. May 19, NBC News - (National) Takata recalling 33.8M air bags, biggest ever in 
U.S. The National Highway Traffic Safety Administration announced May 19 a 
settlement with the Takata Corporation in which the air bag manufacturer agreed to 
declare 33.8 million of its inflator mechanisms defective, leading to the largest 
recorded U.S. auto recall. The defect has led to recalls from 10 automakers and 
included 17 million vehicles in the U.S. prior to the May 19 announcement. 

Source: http://www.nbcnews.com/business/autos/takata-expected-declare-33-8m- 
vehicles-defective-report-says-n361446 
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Defense Industrial Base Sector 

Nothing to report 
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Financial Services Sector 

3. May 20, Reuters - (International) Major banks admit guilt in forex probe, fined $6 
billion. Citigroup, JP Morgan, Barclays, the United Bank of Switzerland (UBS), and 
the Royal Bank of Scotland (RBS) agreed to plead guilty and pay $6 billion in fines 
May 20 in a settlement with the U.S. Federal Reserve and U.S. Department of Justice 
(DOJ) to resolve charges of foreign currency exchange manipulation that had occurred 
until regulators started punishing banks for the misconduct in 2013. The settlement 
represents the largest antitrust fines issued by the DOJ in agency history. 

Source: http://www.reuters.com/article/2015/05/2Q/us-banks-forex-settlement- 
idUSKBN0050CQ20150520 

4. May 19, Orlando Sentinel - (Florida) State finds 103 credit-card skimmers in 3- 
month inspection of gas pumps. Florida’s Commissioner of Agriculture and 
Consumer Services announced May 19 that a 3-month inspection of 7,571 gas pumps 
revealed 103 credit-card skimming devices across the State. The Florida Petroleum 
Council and the Florida Petroleum Marketers and Convenience Store Association plan 
to train employees to be vigilant for skimmers. 

Source: http://www.orlandosentinel.com/business/os-gas-pump-skimmers-201 505 19- 
story .html 

5. May 19, Reuters - (National) U.S. regulator says PayPal to pay $25 min over credit 
product problems. The U.S. Consumer Financial Protection Bureau (CFPB) 
announced allegations May 19 that PayPal illegally signed consumers up for an online 
credit product without their knowledge or permission, and has issued the company to 
pay $25 million in fines to the government and consumer refunds. The CFPB also 
alleged that PayPal Credit failed to honor advertised promotions and charged 
illegitimate late fees when Web site problems prevented customers from making 
payments. 

Source: http://www.reuters.com/article/2015/05/19/financial-regulation-paypal- 
idUSLlN0YAlAD20150519 
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Transportation Systems Sector 

6. May 20, NBC News - (Louisiana) Evacuations ordered after chemical cars derailed 

in Louisiana. Six tankers from a Union Pacific train carrying sodium hydroxide, 
propylene oxide, and propylene dichloride derailed in Addis May 19, prompting the 
parish’s Office of Homeland Security to declare a state of emergency and a mandatory 
evacuation for residents within 1,000 feet of the area while officials cleared the scene. 
The cause of the derailment is suspected to be damaged track. 

Source: http://www.nbcnews.com/news/us-news/evacuations-ordered-after-chemical- 
cars-derail-louisiana-n36 1661 
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7. May 20, Associated Press - (Georgia) 2 dead as fiery crash shuts down Interstate 16 
near Savannah. A portion of Interstate 16 near Savannah was closed for several hours 
May 19 following a fatal accident that involved 5 vehicles and killed 2 people. 

Source: http://onlineathens.com/local-news/2015-05-19/2-dead-fiery-crash-shuts- 
down-interstate- 1 6-near-savannah 

8. May 19, Reuters - (National) UPS to pay $25 min to settle some allegations over 
delivery times. The United Parcel Service (UPS) agreed to pay $25 million to settle 
with the Federal Government and the State of New Jersey May 19 after a former UPS 
employee alleged that UPS knowingly recorded inaccurate delivery times from 2004 to 
2014 on packages guaranteed for next-day delivery, keeping customers from being 
eligible for refunds. The Federal government as well as 19 states, the District of 
Columbia and the cities of Chicago and New York were also plaintiffs in the suit. 
Source: http://www.reuters.com/article/2015/Q5/19/usa-iustice-ups- 
idUSLlNOYAl 3X201 505 19 

9. May 19, Providence Journal - (Rhode Island) Mail sorters among four charged with 
stealing $1.6M in treasury checks from Providence postal center. Four Providence 
residents, including 2 postal workers, were charged with allegedly stealing more than 
$1.6 million in U.S. Treasury checks from the Providence Processing and Distribution 
Center after an investigation revealed that stolen checks were sold on the street at 20 
percent of the value while others were deposited into fraudulent bank accounts that 
were later drained. 

Source: http://www.providenceioumal.com/article/20150519/NEWS/150519233 

10. May 19, WBKO 13 Bowling Green - (Kentucky) Rockcastle County crash kills 2, 
closes Southbound 1-75. All lanes of southbound Interstate 75 near mile marker 71 in 
northern Rockcastle County were closed for several hours May 19 while officials 
investigated a fatal accident that involved 2 vehicles and killed 2 people. 

Source: http://www.wbko.com/home/headlines/Rockcastle-County-Crash-Kills-2- 
Closes-Southbound-I-75-304300671.html 
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Food and Agriculture Sector 

11. May 19, Washington Times; Associated Press - (Iowa) Iowa reports 2 more chicken 
farms, turkey farm with bird flu. Iowa officials reported May 19 that the avian flu 
was found at 3 additional sites in the State including a turkey farm in Buena Vista 
County with 24,000 birds, 2 chicken farms in Sioux County with 250,000 birds, and a 
backyard flock of 15 chickens, bringing the total number of cases in the State to 60 
with 26 million birds culled. 

Source: http://www.washingtontimes.com/news/2015/mav/19/iowa-reports-2-more- 
chicken-farms-turkey-farm-with/ 
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Water and Wastewater Systems Sector 

12. May 19, KSBY 6 San Luis Obispo - (California) Large crude oil spill along southern 
Santa Barbara County coastline. Authorities reported May 19 that an estimated 

21.000 gallons of crude oil spilled onto the coastline of Refugio State beach in Santa 
Barbara County, resulting in a 4-mile wide oil slick and a multi-agency response. The 
cause of the leak remains under investigation and the coastline and nearby 
campgrounds are closed until further notice. 

Source: http ://w w w .ksb y .com/storv/29 1 08637/approximatel y-2 1 000- gallons-of-crude- 
oil-spill-along-santa-barbara-coastline 

13. May 19, KNSD 39 San Diego - (California) Thousands of gallons of treated sewage 
spills in San Luis Rey River: officials. Officials reported May 19 an estimated 

154.000 gallons of treated sewage leaked from a pressurized treated-sewer main into a 
North County drainage canal which prompted warning signs to be posted along the San 
Luis Rey River. The river is not discharging into the ocean at this time. 

Source: http://www.nbcsandiego.com/news/local/Thousands-of-Gallons-of-Treated- 
Sewage-Spills-into-San-Luis-Rev-River-Qfficials-304309551.html 



T Return to top i 



Healthcare and Public Health Sector 

14. May 20, Knoxville News Sentinel - (National) Lawsuit: Cancer charities built 
multimillion-dollar fraud empire. The U.S. Federal Trade Commission along with 
agencies in all 50 States filed a joint lawsuit May 18 against Knoxville-based Cancer 
Fund of America, its 3 affiliated nonprofits, and the individuals who run the charities 
for allegedly using the $187 million raised for personal use. Three individuals and 2 of 
the charities negotiated settlements with the government totaling over $200 million. 
Source: http://www.knoxnews.com/news/local-news/ftc-states-file-complaint-against- 
knoxville-charity 92306448 

15. May 20, Associated Press - (National) Judge approves $200 million settlement in 
2012 meningitis outbreak. A Federal bankruptcy judge approved May 19 a $200 
million settlement with the now-closed New England Compounding Center pharmacy 
in Massachusetts following a 2012 fungal meningitis outbreak that killed 64 people and 
sickened more than 750 others across 20 states as a result of tainted drugs produced by 
the pharmacy. The settlement will be distributed among the victims and 14 former 
employees of the compounding center face Federal charges. 

Source: http://www.timesfreepress.com/news/local/storv/2015/may/20/iudge-approves- 
200-million-settlement-2012-meningitis-outbreak/305274/ 

16. May 19, Lower Hudson Valley Journal News - (New York) Data breach may have hit 
White Plains Hospital. White Plains Hospital in New York notified about 1,100 
individuals May 19 who visited the emergency department between February 2013 and 
March 2015 that their personal information, including Social Security numbers, may 
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have been compromised by a former employee at Medical Management, a medical 
billing company. The hospital is included in a list of several other health care facilities 
impacted by the actions of the former employee, who copied data from the system. 
Source: http://www.lohud.com/storv/news/crime/2015/05/19/data-breach-white-plains- 
hospital/27607717/ 
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Government Facilities Sector 

17. May 19, WDIV 4 Detroit - (Michigan) School in Center Line closed for day after 
another bomb threat. The Michigan Mathematics and Science Academy in Center 
Line was evacuated and closed May 19 due to a hoax bomb threat for two consecutive 
days. Police are investigating the threat. 

Source: http://www.clickondetroit.com/news/school-in-center-line-closed-for-day- 
after-another-bomb-threat/33 1 025 1 6 



For another story, see item 12 
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Emergency Services Sector 

Nothing to report 
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Information Technology Sector 

18. May 20, Softpedia - (International) TLS protocol flawed, HTTPS connections 
susceptible to FREAK-like attack. Cryptography and security researchers discovered 
that approximately 8.4 percent of the top one million domains containing mail and web 
servers are vulnerable to an attack dubbed Logjam, in which an attacker could 
compromise a secure communication between a client and server by downgrading the 
transport layer security (TLS) connection to 512-bit export- grade cryptography due to 
left over variants of the Diffie-Hellman cryptographic key exchange mechanism from 
the 1990s. The attack method is similar to the one used in the Factoring RSA Export 
Keys (FREAK) attacks from early 2015. 

Source: http://news.softpedia.com/news/TLS-Protocol-Flawed-HTTPS-Connections- 
Susceptible-to-FREAK-Like-Attack-481744.shtml 

19. May 20, Securityweek - (International) Millions of routers vulnerable to attacks due 
to NetUSB bug. Security researchers at SEC Consult discovered a kernel stack buffer 
overflow vulnerability in NetUSB drivers developed by Taiwan -based KCodes, in 
which an unauthenticated attacker can execute arbitrary code or cause a denial-of- 
service (DoS) condition by specifying a computer name longer than 64 characters when 
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the client connects to the server. The driver is found in millions of routers from vendors 
including Netgear, TP-Link, ZyXEL, and TRENDnet. 

Source: http://www.securitvweek.com/millions-routers-vulnerable-attacks-due-netusb- 
bug 

20. May 19, Threatpost - (International) Google fixes sandbox escape in Chrome. Google 
patched 37 bugs in Chrome version 43, including 6 high-risk sandbox-escape, cross- 
origin bypass, and use-after-free vulnerabilities discovered by various security 
researchers. 

Source: https://threatpost.com/google-fixes-sandbox-escape-in-chrome/112899 

21. May 19, Threatpost - (International) Malvertising leads to Magnitude exploit kit, 
ransomware infection. Security researchers at Zscaler discovered that attackers are 
using malicious ads and 302 cushioning attacks to direct users to sites hosting the 
Magnitude exploit kit (EK), which in turn infects users with CryptoWall ransomware. 
The researchers reported that most of the threat infrastructure for these attacks is 
housed in Germany. 

Source: https://threatpost.com/malvertising-leads-to-magnitude-exploit-kit- 
ransomw are-infection/ 1 12894 



Internet Alert Dashboard 



To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT ISAC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 
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Communications Sector 

22. May 19, Associated Press - (National) Nashville radio show fined $1 million for fake 
emergency broadcast. The U.S. Federal Communications Commission fined 
iHeartMedia $1 million May 19 after an October 2014 incident where an Emergency 
Alert System (EAS) tone was misused on the Nashville-based program “The Bobby 
Bones Show” and was sent to more than 70 affiliated stations across the nation. In 
addition to the fine, iHeartMedia is required to implement a comprehensive plan and 
delete EAS tones from its audio production libraries. 

Source: http://www.knoxnews.com/business/radio-show-fined-l-million-for-fake- 
emergency-broadcast 00045265 
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Commercial Facilities Sector 

23. May 20, WDJT 58 Milwaukee - (Wisconsin) Apartment fire displaces 36 people in 
West Bend. Thirty-six residents at the Rivercrest Apartment complex in West Bend, 
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Milwaukee, were displaced due to a fire on the main floor and basement of the 16-unit 
building May 19. The West Bend fire department extinguished the fire and the incident 
is under investigation. 

Source: http://www.cbs58.com/story/29111271/apartment-fire-displaces-36-people-in- 
west-bend 



24. May 20, Tampa Bay Times - (Florida) Firefighter hurt in huge storage facility fire in 

Valrico. A 3-alarm fire May 20 at the ExtraSpace Storage facility in Valrico, Florida in 
Hillsborough County damaged at least 48 storage units. Two firefighters suffered 
injuries and crews spent over 3 hours working to contain the fire. 

Source: http://www.tampabav.com/news/publicsafetv/fire/firefighter-hurt-in-huge- 
storage-facility-fire-in-valrico/2230360 

25. May 20, WAVY 10 Portsmouth - (Virginia) Massive fire at Va. Beach apartment 
complex. A 2-alarm fire in Virginia Beach at the Legends at the Beach apartment 
complex began on the front side of the complex, displacing 23 people and damaging 16 
apartment units May 19. Crews contained the fire and the incident is under 
investigation. 

Source: http://wavv.com/2015/05/19/massive-fire-at-va-beach-apartment-complex/ 

26. May 20, KDVR 31 Denver - (Colorado) Residents escape, dog rescued from three- 
alarm apartment fire in Fort Collins. A 3-alarm fire May 20 at the Brookview 
Apartment complex in Fort Collins prompted the evacuation of residents and caused 
damage to 12 units. Fire crews announced that the fire began in the attic of the building 
and no injuries were reported. 

Source: http://kdvr.com/2015/05/2Q/residents-escape-dog-rescued-from-three-alarm- 
apartment-fire-in-fort-collins/ 

27. May 20, Reuters - (Texas) About 1,000 weapons found at a scene of deadly Texas 
gang fight. The Central Texas Marketplace Shopping Center in Waco reopened May 
20 after a shootout between 5 rival motorcycle gangs left 9 people dead and at least 1 8 
others injured May 17. Police took 170 people in custody in connection to the brawl 
and recovered about 1,000 weapons including firearms and knives from the scene. 
Source: http://www.reuters.com/article/2015/05/2Q/us-usa-texas-bikers- 
idUSKBN0Q5 1Q420150520 

28. May 20, Associated Press - (Wisconsin) Store destroyed by fire in Milwaukee. 
Mother’s Food & Liquor store in Milwaukee suffered $1 million in damages in a May 
19 fire that destroyed the building. Crews contained the fire and stayed on site for 
several hours. 

Source: http://www.nbcl5.com/home/headlines/Store-destroyed-bv-fire-in-Milwaukee- 
304413191.html 
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Dams Sector 
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Nothing to report 
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Department of Homeland Security (DHS) 

DHS Daily Open Source Infrastructure Report Contact Information 

About the reports - The DHS Daily Open Source Infrastructure Report is a daily [Monday through Friday] 
summary of open-source published information concerning significant critical infrastructure issues. The DHS Daily 
Open Source Infrastructure Report is archived for 10 days on the Department of Homeland Security Web site: 
http://www.dhs.gov/IPDailyReport 

Contact Information 

Content and Suggestions: Send mail to cikr.productfeedback@hq.dhs.gov or contact the DHS 

Daily Report Team at (703) 942-8590 

Subscribe to the Distribution List: Visit the DHS Daily Open Source Infrastructure Report and follow 

instructions to Get e-mail updates when this information changes . 

Removal from Distribution List: Send mail to support @ govdelivery.com . 



Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original 
source material. 
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